ObliqueRAT is a Windows remote access trojan associated with Transparent Tribe, also tracked as APT36. It has been used in cyber-espionage operations targeting government, military, and related personnel, particularly in South and Southeast Asia, with repeated reporting tying it to campaigns against Indian government and defense interests. The malware is commonly delivered through malicious Microsoft Office documents containing macros, including phishing lures and spreadsheet or document-based social engineering, and has also been observed in narrowly targeted attacks delivered through VBS-laced documents. In some campaigns, payloads were disguised within benign-looking image files or delivered via actor-controlled websites and lookalike file-sharing infrastructure.
Once executed, ObliqueRAT provides persistent remote access and supports a broad set of host reconnaissance and collection functions. Reported capabilities include enumerating processes, host names, user identifiers, drives, directories, and files; checking usernames and process names against internal blocklists; and gathering host fingerprinting information. It can capture screenshots, collect webcam images, identify removable or pluggable drives, and extract files from removable media. It also supports copying files of interest, staging data locally, splitting large files into smaller chunks for transfer, receiving files from command-and-control, and executing arbitrary command lines. Persistence has been observed through creation of shortcuts in the user Startup folder.
Operational reporting indicates overlap in tradecraft and delivery mechanisms with CrimsonRAT, another Transparent Tribe malware family, and some analyses have linked the two through shared malicious documents, macros, and infrastructure. ObliqueRAT appears intended to establish footholds and maintain long-term remote access for intelligence collection and data theft rather than disruptive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The main payload employed by Transparent Tribe in most of associated campaigns are variants of Crimson and Oblique RATs, which indicates that the objective of their activity is obtaining foothold and persistent remote access.
domain names similar to file-sharing services are used to trick the general audience into downloading malicious XLS files with macros that download malware samples of CrimsonRAT, ObliqueRAT, and Poseidon families.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious VBA script in the maldocs is activated once the user enters the correct password for the document.
Command Code =”7” Command Data=<command_line> Execute given command line on the endpoint with a high priority
For the purposes of this post, we're focusing on Excel VBA code and its evolution over time.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Poseidon malware which targets government employees who use UNIX-based systems for their jobs by mimicking Kavach service... Malicious documents are disguised as conference agendas, invitations, and diplomatic reports... guidelines, policies, and activity plans... advisories, or top secret briefings.
The ZIP file is subsequently deleted from the endpoint after exfiltration.
This command is used to delete (remove) a file specified by the C2 server from the endpoint.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
This command is aimed to trigger the implant to discover the category of various drives on the endpoint.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
The implant then connects to its C2 server using hardcoded values of its IP Address and Port Number.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT family referenced due to code similarity with a stealer deployed in an APT36-attributed phishing campaign.
RAT family referenced via code similarity to a stealer used in APT36-linked phishing activity against Indian aerospace/government targets.
Referenced only as an example source related to lookalike domains used to deliver malware; no further malware-specific behavior is described in the content.
A remote access trojan referenced as another malware family used by Transparent Tribe in malicious XLS macro campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.